Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack

2026-03-30T01:24:10Z233ef0fe0edfc8d2d1f38942600757ba71adb6556c8e3c7a4a5a3086e88c5183
AitMCVE-2025-53521CVE-2026-3055KEVPyPIactive-exploitationbackdoorchina-linkedcloudflare-turnstile-evasion','ransomware','GenieLocker','telecocredential-harvestdark_swordexploitiOS-exploitiran-linkedknown-exploited-vulnerabilitymemory-overreadopen-vsxphishingpre-publish-bypassrussia-linkedspear-phishingstate-sponsoredsupply-chainvs-code-extensionvulnerability

What happened

A batch of The Hacker News reports (late Mar 2026) highlights pervasive, high-impact activity: Iran-linked Handala breached FBI Director Kash Patel’s personal email and leaked materials and also deployed a wiper against Stryker; multiple critical vulnerabilities are under active reconnaissance/exploitation (Citrix NetScaler memory overread CVE-2026-3055, and F5 BIG-IP APM CVE-2025-53521 added to CISA’s KEV); and Russian-linked TA446 is using the DarkSword iOS exploit kit in targeted spear-phishing. Supply-chain and software distribution compromises by TeamPCP (malicious telnyx PyPI packages, l

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
233ef0fe0edfc8d2d1f38942600757ba71adb6556c8e3c7a4a5a3086e88c5183
Enrichment time
2026-03-30T01:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.